Quiz 5 Question 1 of 20

An EDR console shows a process tree: winword.exe → cmd.exe → powershell.exe -enc [base64 string] → net.exe user /add backdoor P@ssw0rd. Which MITRE ATT&CK techniques are represented, and what immediate action should be taken?

Select an answer to reveal the explanation.

Motivation